Insecure Direct Object Reference in MphRx's Minerva Product
CVE-2026-5779
9.4CRITICAL
What is CVE-2026-5779?
An insecure direct object reference vulnerability exists in MphRx's Minerva version 3.6.0, specifically at the '/minerva/user/updateUserProfile' endpoint. This vulnerability enables an authenticated user to alter the details of other registered users, including email addresses, and to initiate a password reset via the '/webconnect/#/forgotPassword' endpoint. Such exploitation can facilitate potential account takeover, putting user data at risk.
Affected Version(s)
Minerva 3.6.0
